Sceawere
Vulnerability Detail
CVE-2026-103101UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Pexip Infinity Denial-of-Service Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.6
- Creation Date
- 4h ago
- Vendor
- Pexip
- Product
- Infinity
- Attack Type
- CWE-770 Allocation of Resources Without Limits or Throttling
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.6",
"pubDate": "2026-09-30T03:16:59.033Z",
"pubdate": "2026-09-30T03:16:59.033Z",
"executiveSummary": "Pexip Infinity versions 30.0 through 40.x (prior to 41.0) contain a critical security vulnerability stemming from improper input validation within the web server component. This flaw allows a remote, unauthenticated attacker to induce a denial-of-service (DoS) condition, rendering the affected Pexip Infinity node inaccessible. The vulnerability represents a significant operational risk, as successful exploitation disrupts real-time communication services provided by the node. By sending specifically crafted, malicious input to the web server, an attacker can trigger a failure state that forces the node offline, necessitating administrative intervention to restore functionality. No user interaction or elevated privileges are required to initiate the attack, making it highly exploitable over the network.",
"technicalDetails": "The vulnerability is rooted in the Pexip Infinity web server's failure to adequately sanitize and validate incoming HTTP requests. The web server component does not implement robust constraints on input handling, allowing an attacker to supply malformed or unexpectedly large data packets that exceed the expected structure of the application layer protocols. When the web server parses this tainted input, it triggers an unhandled exception or resource exhaustion state within the process memory space or the event loop, leading to the abrupt termination or hang of the web service process.\nThe exploitation flow begins with a network-level connection to the Pexip Infinity node's web interface. An attacker transmits an HTTP request containing a crafted payload designed to bypass existing validation checks. Because the vulnerability exists at the entry point of the web server, the input processing logic fails to safely buffer or validate the data before it is handed off to backend functions responsible for request routing or state management. The resulting instability propagates through the system, eventually causing the node to become unresponsive.\nKey characteristics of the vulnerability include:\n- Affected Versions: Pexip Infinity 30.0 through 40.x, before 41.0.\n- Vulnerable Component: Integrated web server interface.\n- Authentication Requirements: None; the attack is possible without prior authentication.\n- Network Exposure: The attack is executable via standard network protocols, specifically targeting exposed web management or signaling interfaces.\n- Payload Behavior: The payload is designed to exploit the parsing logic of the web server. Depending on the specific input, this may cause a buffer overflow, a null pointer dereference, or an infinite loop that consumes all available CPU or memory resources associated with the process.\n- Post-exploitation Impact: The node effectively crashes or enters a 'zombie' state where it stops processing legitimate media, signaling, and management traffic. This results in the complete loss of service for any endpoints connected through the impacted node. Restoration of the node typically requires a service restart or a full system reboot, as the process is incapable of self-recovery from the triggered fault state."
}